CVE-2015-7973 — Authentication Bypass by Capture-replay in Freebsd
CWE-254CWE-294 — Authentication Bypass by Capture-replayCWE-119 — Improper Restriction of Operations within the Bounds of a Memory BufferCWE-20 — Improper Input ValidationCWE-200 — Sensitive Information ExposureCWE-287 — Improper AuthenticationCWE-399CWE-400 — Uncontrolled Resource Consumption24 documents11 sources
Severity
6.5MEDIUMNVD
EPSS
8.6%
top 7.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30
Latest updateMay 13
Description
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 2.2 | Impact: 4.2
Affected Packages6 packages
Also affects: Ubuntu Linux 12.04, 14.04, 16.04
🔴Vulnerability Details
3📋Vendor Advisories
18Cisco▶
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016↗2016-01-28